CVE-2025-0746

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jan 30, 2025
CWE ID 79

Summary

CVE-2025-0746 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting EmbedAI versions 2.1 and below. This issue enables authenticated attackers to inject malicious JavaScript code through the "/embedai/users/show/<SCRIPT>" endpoint by crafting a malicious URL. When an unsuspecting user opens the malicious URL, the malicious JavaScript code is executed, potentially compromising their session or stealing sensitive information. Attackers can use this vulnerability to launch various attacks, including session hijacking, identity theft, and data exfiltration. It is important for EmbedAI users to upgrade to the latest version or implement appropriate XSS protection mechanisms to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share